What you need to know today.
GitLab and PaperCut face active exploitation of critical flaws; multiple other RCE and auth bypass vulnerabilities disclosed.

GitLab has released patches for multiple critical vulnerabilities, including CVE-2026-85706, a path traversal flaw allowing unauthenticated users to read arbitrary files. This vulnerability has been actively exploited in the wild shortly after its disclosure and is now listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. The advisory highlights that exploitation attempts were observed within a day of the patch release, underscoring the urgency for affected organizations to update. The issue affects GitLab CE/EE versions prior to 19.1.8, 19.2.6, and 19.3.2. Another critical vulnerability, CVE-2026-87719, allows authenticated users with Duo Chat access to obtain Advanced Settings, with patches available in the same release. As The Register reported, the rapid exploitation of CVE-2026-85706 demonstrates a trend of attackers moving quickly to weaponize newly disclosed vulnerabilities.
Critical vulnerabilities in PaperCut NG and MF, CVE-2026-81578 and CVE-2026-82078, are being actively exploited, with attackers leveraging hundreds of AI agents to compromise over 440 instances. CVE-2026-81578, an improper access control flaw in the web management interface, and CVE-2026-82078, an unsafe dynamic class loading vulnerability, allow for remote code execution. As Help Net Security reported, the exploitation campaign has targeted educational institutions and other organizations, with attackers planting remote access tools on compromised servers. Patches are available for these vulnerabilities, and organizations are urged to update immediately. The sophisticated nature of the attack, involving numerous AI agents, highlights the evolving threat landscape.
A critical unauthenticated Remote Code Execution (RCE) vulnerability, CVE-2026-25470, has been identified in the ACPT (Pro) - Custom Post Types Plugin for WordPress versions up to 2.0.47. This flaw allows unauthenticated attackers to execute arbitrary code on affected WordPress sites, posing a significant risk to website integrity and data security. While no specific exploitation details or news articles were provided for this CVE, its critical severity and RCE capability warrant immediate attention from WordPress administrators. Updating the plugin to a patched version is crucial to mitigate this risk.
Apache Artemis and ActiveMQ Artemis are affected by CVE-2026-27446, a critical vulnerability where missing authentication for critical functions allows unauthenticated remote attackers to force a target broker to establish an outbound Core federation connection. This could lead to various security compromises depending on the broker's configuration and network exposure. The vulnerability stems from improper handling of authentication for core protocol interactions. Administrators of Apache Artemis and ActiveMQ Artemis should ensure their systems are updated to versions that address this security flaw to prevent potential exploitation.
CVE-2026-90919, a critical remote code execution vulnerability in LightLLM through version 1.2.0, has been disclosed. The vulnerability exists in the Config Server's unauthenticated /visual_register WebSocket endpoint, which passes client frames directly to pickle.loads() without proper validation. This allows attackers to execute arbitrary code on the server by sending crafted WebSocket messages. Given the nature of LLM deployments, this vulnerability could have significant implications for systems processing sensitive data or running critical operations. Users of LightLLM should update to a patched version as soon as possible.
Several other critical vulnerabilities have been disclosed, including an authentication bypass in MaxSite CMS through 109.6 (CVE-2026-87929) due to a hardcoded session encryption key, and an improper authorization flaw in Google Chrome extensions prior to 153.0.8010.36 (CVE-2026-87544) that could allow bypassing privileged page restrictions. Adobe ColdFusion is affected by an 'Eval Injection' vulnerability (CVE-2026-48273) leading to arbitrary code execution. Additionally, critical flaws were found in Contec Co., Ltd. products (CVE-2026-82787), Forgejo (CVE-2026-89094), s-pms (CVE-2026-71801), SSO Master (CVE-2026-79577), HubCore (CVE-2026-75171), and FreeIPMI (CVE-2026-85507), along with vulnerabilities in the Linux kernel (CVE-2026-74474, CVE-2025-38660). Pingidentity (CVE-2026-21391) and Joomla extensions (CVE-2026-85192) also have critical security issues that require attention.